Description
A broad DB security-group CIDR can allow addresses beyond the applications and administrators that need a connection. A private address range does not make every system in it trusted.
A longer prefix reduces the address count, but no prefix length alone guarantees appropriate access. Restrict the range using actual clients and connection paths.
Potential impact
- Systems without a business need may attempt database connections.
- Accumulated broad exceptions make allowed clients and change impacts harder to track.
Remediation
- Identify actual client addresses and administration paths, then allow only the required scope.
- In current VPC security groups, use application security groups as sources where appropriate and restrict actual database ports.
- Manage exception owners and expiry dates, and verify required connections and blocked access after changes.
Examples
These are historical DB Security Group CIDR comparisons. The resource was removed in Terraform AWS provider 5.0. Use VPC security groups for current environments and choose ranges for the actual approved clients.
Before
resource "aws_db_security_group" "db_sg" {
name = "rds_sg"
ingress {
cidr = "10.0.0.0/24"
}
}
10.0.0.0/24 contains 256 IPv4 addresses. Check whether each needs database access.
After
resource "aws_db_security_group" "db_sg" {
name = "rds_sg"
ingress {
cidr = "10.0.0.0/25"
}
}
10.0.0.0/25 contains 128 IPv4 addresses. A smaller range still needs unnecessary addresses excluded.